Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
Fixed in: 3.3.1, 4.0.5
details
- Finding IDs
- F-AWS-ENCRYPTION-SDK-PYTHON-001
- CVE
- CVE-2026-6550
- GHSA
- GHSA-v638-38fc-rhfv
- Status
- patched
- Fixed in
- 3.3.1, 4.0.5
- Recorded credit
- acknowledgement: 1seal.org
- Note
- GHSA-v638-38fc-rhfv · AWS-2026-017
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- CVSS assessment
- AMZN CNA; v3.1; 4.7; observed 2026-09-24
- Upstream title
- Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
F-AWS-ENCRYPTION-SDK-PYTHON-001: Verification failures. Cached key material bypasses a required key-commitment check. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-ENCRYPTION-SDK-PYTHON-001
Security area (1seal assessment): Integrity. Shared cached encryption materials can bypass key commitment, undermining the binding between ciphertext and plaintext. Reviewed 21 Sep 2026.